Design 24: pair credentials are sealed to the operator too

This commit is contained in:
2026-09-21 00:36:30 +02:00
parent 050a2d08e8
commit 8607d21110
+5 -3
View File
@@ -108,9 +108,11 @@ foundation is raised with, so the mesh is handed over with nothing well-known in
the installer's and is not yet built; until it is, the fixed credentials are the as-is and are
said so in [21](21-the-installation-in-full.md).
What is not yet sealed to the operator: a module's vault-provided secret — the pair credential of
[13](13-credentials-and-their-rotation.md). That is the next increment, the same column and the
same call on the pair table.
A module's vault-provided secret — the pair credential of
[13](13-credentials-and-their-rotation.md) — is sealed to the operator the same way, as is every
credential a provider grants; the export names each entry by the node and module that hold it and
the name they know it by, and says whether it is a module's own secret or a pair credential, so
recovery addresses both alike.
## Beyond generate and hold